Tell HN: OpenAI keeps re-enabling the 'allow training' setting

4 points by jacquesm ↗ HN
I've reset this more than once and the last time I made a careful note of when I did it and to my surprise I found it re-enabled when I checked just now. Make sure you check this thing to see if it hasn't been re-enabled if you believe it to be off right now.

144 comments

[ 0.21 ms ] story [ 9.2 ms ] thread
If you document it properly then this basically destroys any legal claim they can make about that checkbox.
Out of curiosity, how one is supposed to "document it properly"?
Claude is actually quite good at legal advice (certainly better than most HN commenters), and it gives quite a few options.
You can obtain a cryptographic proof by recording the tls exchange, including the keys

You need to use a tls intercepting proxy for that.

I couldn't find any ready-made tool unfortunately, there's tlsnotary.org but it seems far from simple.

So basically I record what the browser sends to the server when I click the toggle and the server response?

I wonder how I can attach a timestamp that cannot be faked.

Look into court-grade eDiscovery Software.

https://en.wikipedia.org/wiki/Electronic_discovery

Specifically forensic web preservation or web capture tools.

That Wikipedia article seems to have no bearing on the issue; there's not even any log on a normal user's computer of having or not having clicked a checkbox.

> If they made it impossible for you to prove that you clicked a checkbox or not, then, logically, the burden of proof is on THEM

Even in Europe the only "proof" that's required to companies is a log or database entry (both easily manipulated); if a user strongly disputed to have done it and sued the company for that, maybe you'd able to obtain some investigation on their systems.

If you have the TLS session with all the keys, that's signed with the server's key, so it's basically certified by them themselves.

They could only claim that it's been faked by claiming that you stole their TLS private key.

> Make sure you check this thing to see if it hasn't been re-enabled if you believe it to be off right now.

Or simply switch to a competitor. Assuming this is not just a bug, why would one stand for such disrespectful and sneaky behavior?

what competitor?

the x20 Max plan for Claude gives you way lover limits.

Bedrock is an option. Multiple platforms with solid data sovereignty.

If you don't want them slurping your data, you're gonna have to pay more.

Same as it ever was.

Well, it’s a tradeoff. What do you prefer? To go with the service provider known to be shady but gives you lots of free stuff or the one that might be less shady and gives you less free stuff?
My cynicism fails me on this matter... do I cynically believe that these companies keep deliberately and routinely re- or un-checking these checkboxes because of the obvious benefits of "whoopsie guess you allowed these after all"? Or do I cynically believe that they are just so completely incompetent and inept at the simple act of maintaining settings that there may be a number of these that are not entirely intentional? As evidenced by the number of other bugs and configuration failures and random settings changes on update I see in other places? Sure, these sorts of settings sure seem to get spontaneously flipped more often than the other ones but they aren't the only settings I've seen get nuked on updates.

Now, obviously, considered as a whole, I think we're looking at "both". But when I wonder about specific cases like this one, that doesn't help.

Yeah this could just be some vibeslop doing normal computer stuff. AI agents are famously incompetent at reasoning about database transactions. This seems like the sort of failure you get when you try to do distributed systems without knowing how--brings us back to the early mongodb days. Or it could be deliberate. Or, as you say, both.

Either way, is this a company you want to trust with intimate secrets? "Oh, but they passed SOC2!" Lol.

“Autoplay” and YouTube case in point:

- Autoplay transitioned to a per-device setting… suddenly default-on on every new device you log in to.

- Watching a video with computer-to-TV account connection? Automatic “TV queue,” a concept absent from the TV app, with incomprehensible behavior for how it’s used, so now videos are auto-played anyway.

- Watching a video from a playlist? Autoplay cannot be turned off.

Is it simply bad/absent product management and product design? Or is it actively user-hostile decisions meant to prop up view numbers and continue to have the users hooked on YouTube?

Interestingly your cynicism does not seem to account for OP?

I actually found my setting was enabled today when I know it was disabled before, so I’m inclined to agree with OP. I just think it was worth mentioning that there are other cynical takes you seem to have left out.

I've noticed that toggle sets a local storage entry, but the value of it doesn't appear to matter at all for new tab loads. I hoped it's "just" a UI bug, but some agent-driven reverse engineering of the page should reveal the answer, as well as how intentional it was.
Based on their behavior over the past few years, why would you assume that checkbox even does anything at all?
The vast majority of OpenAI users don’t follow the industry drama and have no idea how terrible the company is. They’ve been really good at getting good press coverage, with journalists who will repeat the company narrative. Even when critical it is very often framed within the narrative they established
> They’ve been really good at getting good press coverage

Same holds for most big corps from what I can tell. If you really do a deep dive into the scandals over the years, you’ll probably see most have barely reached the news or if they did then it’s usually a quite bland criticism like “anti-competitive practices” or a poor HVAC at a certain factory. I think a lot more is hidden than we think

While that is true, you also have no reason to assume OP is being truthful or correct here given that they have shown 0 proof of what they're saying. Yes, you can then pile on "OF COURSE ITS OPENAI LOL YOU THINK THEY CARE ABOUT PRIVACY LOL" but where have we established OP's premise is even correct? Can anyone else also report this? So is it just OpenAI specifically messing with OP?
All things being equal, AI actually enables this extremely hyper-personalized kind of gaslighting.
If it didn't do anything, they wouldn't keep re-enabling it.
Did you encounter it too? (Trying to get a rough estimate of how many people are reporting it vs how many people aren't.)
This kind of cynicism is not really useful. As much as we can distrust the company, there is a legal minefield to offer this option in the UI and terms of service and not respect it.
(comment deleted)
Turn on "Advanced Account Security", that prevents model training from being turned on.
Where does it say that? https://chatgpt.com/#settings/Security merely says

Adds the highest level of account security by requiring stronger sign-in methods and applying stricter protections to help prevent unauthorized access.

That is not about model training.

It prevents unauthorized access from OpenAI’s model training.
Documentation is not complete, it also protects your data from being used in training.
Citation?
https://openai.com/index/advanced-account-security/

> Automatic training exclusion. People working with especially sensitive information may opt not to have those conversations used for model training. With Advanced Account Security enabled, that preference is automatic: conversations from those accounts will not be used to train our models.

I've disabled the checkbox many months ago and it's still disabled today. EU citizen, not sure if that's relevant.
Same here, I just happened to check yesterday and hadn’t checked for at least half a year.
Same here on Pro 20x, Switzerland
For me, "Improve the model for everyone" was "On", although I disabled a similar-sounding checkbox in the past (Germany).
Is there a description of what "Improve the model for everyone" actually means or is it just a straight up *Dark* pattern?
It's pretty clear once you click on it:

> Allow your content to be used to train our models, which makes ChatGPT better for you and everyone who uses it. We take steps to protect your privacy. Learn more

So not in the basement behind a sign saying "Beware of the Leopard" but could also just be "Allow your content to be used to train our models: <Yes|No>".

Could be worse I guess.

What makes you think the company that pirated a big portion of all copyrighted work will care about this checkbox?

At best they’ll “anonymize” the data before adding it to the corpus.

Same for me, I disabled it like 2 years ago and it is still not enabled. Location: Norway (which is for data control purposes = EU)

Edit: I have a pro subscription now but it has also been on a free tier level for perhaps 1.5 of these years.

Lol, "Outrageous that the company that chose to ignore copyright holder claims, chose to ignore my checkbox of intent despite the implied pinky promise".
Ignoring the checkbox is an utterly offensive move, but repeatedly manipulating it contrary to stated consumer intent is a whole other level. I didn't know we were supposed to take 'frontier' literally in every sense of the word.

I have now witnessed this myself after not believing this at first. Of course, screenshots etc. will hardly prove anything. This needs a proper third-party audit!

Oh they aren't a frontier on this. Undoing user configuration is well tested in Windows land.
[delayed]
Reverting... to on? I've seen some stuff in Apple-land where I'm pretty sure it went back to the default option after an update but I've never seen anything get granted more permissions.
[delayed]
Ah, sure, it's annoying but it's never giving new permissions you didn't give it before. And yes "revert to default" is probably not what's happening, but reverting to forcing a specific permission grant when the existing one was superceeded or replaced.
[delayed]
I understand the rationale. The app you granted full disk access three months ago might have significantly changed. You can't reset the permissions for a given app after every update, as you might end up prompting the user three times per week.
The alternative would be keeping a permission granted for an app that might have had an update introducing nefarious behavior, whether intentional or not.

Annoying yes, but least bad.

"Remember my choice", right?:)
> Ignoring the checkbox is an utterly offensive move, but repeatedly manipulating it contrary to stated consumer intent is a whole other level.

I'm not sure why the second one is worse than the first one.

Wall, you can't tell if they're ignoring it, but it's fairly easy to show they're manipulating it. So a cut-and-dry demonstration is worse than a strong suspicion.
One has to remember they're crooks through and through. They're doing it by retoggling the checkbox because it offers them plausible deniability.

"Oh, side effect of a recent update, silly us, we'll improve QA, sorry !".

Or "once again our all-powerful models got away from us ! they did it themselves, the little scamps".

Sounds more like implausible deniability.
You know what they'll say in their defense. "This is an extremely complicated systems, and we apologize that a technical solution was broken in an intricate way. [Insert boilerplate about taking privacy seriously here]"

These companies need to burn.

Somehow it never fails the other way...
Linkedin, Amazon and others have gotten around this by adding a "new" feature, default on. I've gone into privacy settings where everything is unchecked, except a newly added checkbox.

This is apparently enough to hold up the broadly-accepted fiction that its possible to use these services while maintaining privacy and without risk. There's a huge industry of hosting services to handle the needs companies who compete with the primary cloud providers, who can't afford the IP and competitive risk.

OpenAI was caught directly stealing from apple, asking employees to bring in their laptops. Its a polite fiction that companies aren't trying to gain any advantage over the other. There's no effective consequence, and even if they get caught red handed they can litigate for decades.

Pirating copyrighted works is absolutely illegal in most jurisdictions, but pirating every single copyrighted work in the world is somehow exempt from law.

We can't apply plebeian laws or ethics to our benevolent overlords, they are above our worldly worries.

If you break enough laws fast enough, you can become so big that nobody will punish you for national security reasons.
Exactly, they scrape the internet without any regard for copyright and now someone is surprised it happens to them.

What's next, subscribers believe they are paying customers instead of sponsored data providers?

Yes, blame the users.
Up until ~1800, the way societies handled this kind of depravity was to hit the bad actors with sticks or rocks until their skull opened up so the evil spirits could leave their bodies.

It's unfortunate that most societies have outlawed this practice. I'm certain if that were in place today, we wouldn't have this problem.

I've yet to hear any alternative solution that's as effective.

Yes, because if there is one thing societies of the 1700s are known for, it's consumer protection practices.

/s for the /s impaired.

They used to burn witches too. I don't know if it was really effective, though, they kept finding witches all over.
Well, by definition they were proven innocent when they drowned/burned up.
i mean, the entire company is built upon stealing protected artefacts... i'd be skeptical of any radio box that says "hey if you press this we promise we won't steal your data"
Does OpenAI use optimistic UI updates? After you disabled the checkbox, it might have had failed in the backend (and not updated the UI).

Verify with devtools to see if that's the case.

---

for me, Youtube "auto-play" irks the me same way, and turning it off did not actually succeed in the backend, thus kept on left as on

if it walks like a duck and talks like a duck...
It won’t be an option soon enough. I doubt they even honour it now anyway.
Can confirm. I turned off mine last week when I started using it again for Astra. Checked this morning and voila, it was on.

I went ahead and uninstalled the app. Won't be renewing.

I've done the formal opt-out process - like "Make a privacy request" where you fill out a form.

Not sure if that's region specific or something though.

Weird, I'm the opposite. I don't recall ever setting mine and I just checked and it was set to "disallow training".
Is this Settings > Data Controls > "Improve the model for everyone" or is there a "disallow training" somewhere else?
Yes that's what I was referring to. I'm a non paid user but I did pay for a consumer subscription before for a few months.
> I don't recall ever setting mine and I just checked and it was set to "disallow training".

I wonder if the default setting changed for newer accounts.

Odd how much data people are trusting with a company on a monetary cliff edge.

Sure send them all your financial, personal data, they won't ever sell it on to the highest bidder for a new profit stream.

Using it as a therapist, financial advisor, health expert and blackboard has always been a terrible idea.

reminder to consider using an open weights model
I disabled it once, it has always stayed disabled.

So it may or may not happen regularly, but I would not over-index on a sample size of one.

had my account since the gpt 3.5 days, disabled it once and its still disabled. though, now that i have advanced account security enabled, the setting is disabled entirely
I quit OpenAI anything early when when their "do not train on my data" option was broken for several weeks. They are my one and only chargeback when I tried to quit and oops somehow I still got billed.

They are a deeply unethical company by any measure of observation.

Is this the “Improve model for everyone” setting under “Data Controls” or is that a different checkbox?
I also have not seen this, the checkbox has stayed off for me.
Note: Turning off that checkbox is not enough. You also need to fill out the "Do not train on my content" request here:

https://privacy.openai.com/policies?modal=take-control

No you don't. They are different ways in to the same function. It's definitely confusing though, this incorrect claim has been going viral since the navier broo haha